CSIDB logo
Incident

Romanian government's land registry agency

Incident posture

Attack window
Jul 2026
Location
Romania
Status
Unknown
CIA posture
Available to members
Updated
2026-09-03 17:25

Linked entities

Victim
Romanian government's land registry agency
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack on the Romanian government's land registry agency wiped its entire database and caused major disruption to the nation's real estate market. The incident was cited as one of the significant ransomware events in an analysis that noted a 19% rise in attacks compared to the previous month. Analysts highlighted the attack for demonstrating how ransomware groups can delete large datasets, underscoring the importance of reliable backups for recovery.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In July 2026, Comparitech recorded 799 claimed ransomware attacks, marking a 19% increase from June and the second highest month of the year. The analysis, published on August 5, 2026, highlighted several major confirmed incidents, including one affecting the Romanian government's land registry agency. The incident occurred during the broader surge in ransomware activity that saw finance, technology, healthcare, and education sectors experience notable month‑by‑month increases. The land registry agency attack was identified as a ransomware event that led to the wiping of its entire database. This event was noted alongside other significant incidents such as the attack on US healthcare provider AnMad.

The wiping of the land registry agency's database caused significant disruption to Romania's real estate market, as property transactions and records became inaccessible. No further details about the attack vector, ransom demand, or threat actor attribution are provided in the source material. The source does not describe any detection, containment, or remediation actions taken by the agency or authorities. Consequently, the narrative is limited to the confirmed outcome of data loss and the resulting market disruption. The incident remains cited as an example of ransomware groups deleting massive datasets to inflict operational harm.

Sources

Sources available to members: 1 source.

CSIDB